2. Calendar Phishing
Executive summary
Calendar Phishing exploits platforms like Google Calendar, embedding malicious links into invites to bypass email filters and deceive users into clicking without scrutiny.
Real‑world example
According to Bitsight Threat Intelligence, over a period of four weeks more than 4,000 spoofed invites hit approximately 300 organizations. These invites appeared as legitimate meeting requests, often redirecting users to phishing pages disguised as Google Forms or Drawings. A media advisory also flagged similar campaigns using misleading diary entries to lure users.
Impact
This method enables credential harvesting, malware deployment, and unauthorized access to corporate systems.
Strategic Recommendations
- Educate users not to trust unsolicited calendar invites.
- Enable the “Only if sender is known” setting in Google Calendar.
- Keep email defenses and spam filters up to date.
- Monitor invite patterns for unusual domains or sender behavior.
- According to Bitsight Threat Research, rapid spikes in spoofed invites often signal active phishing campaigns targeting specific industries.
3. Captcha Phishing (Fake CAPTCHA)
Executive summary
Captcha Phishing involves tricking users into executing malicious commands under the guise of a CAPTCHA challenge. These fake CAPTCHAs can exploit human trust in verification processes for malware delivery.
Real‑world example
Fake CAPTCHAs have been embedded into seemingly harmless websites or ads. Clicking “I’m not a robot” tricks users into copying a command which they then paste and run via the Windows Run dialog box—installing malware like Lumma Stealer.
Notable malware
Lumma Stealer has been linked to these tactics. It steals data from browsers and crypto wallets, using CAPTCHA-triggered execution to gain access and evade detection.
Impact
This attack circumvents standard security checks, resulting in data breaches, malware infiltration, and system compromise.
Strategic Recommendations
- Train users to recognize suspicious CAPTCHA prompts, especially those requesting system commands.
- Implement robust endpoint protection that catches malicious activity at the browser level.
- Disable or restrict Run dialog and command-line interfaces as a precaution.
- Maintain multi-layered security and incident readiness. According to Bitsight Threat Research, such deceptive tactics are gaining traction and require proactive defense strategies.
Conclusion
Angler Phishing, Calendar Phishing, and Captcha Phishing each exploit common user behaviors and digital tools. According to Bitsight Threat Research, the convergence of human trust with modern phishing techniques makes these methods both effective and difficult to detect. Senior leadership should invest in awareness, automation, layered security, and rapid response to stay ahead of these evolving cyber threats. Learn more about how Bitsight Cyber Threat Intelligence can help.